B
David said:From: "Boris Mohar" <[email protected]>
| http://www.cbc.ca/technology/story/2007/01/04/tech-pdf.html
|
| Comments?
PDF XSS vulnerability
http://www.ciac.org/ciac/bulletins/r-096.shtml
http://isc.sans.org/diary.php?storyid=1999
I don't know about other PDF viewers, but my guess is that some may beI read this as an *Adobe* exploit/bug, not PDF. Says "fixed in Adobe
8". Are other PDF readers vulnerable? Is one vulnerable if there is
no PDF reader?
I have Adobe 8 on a W2K machine. It is vulnerable, at least on thatBeauregard said:I read this as an *Adobe* exploit/bug, not PDF. Says "fixed in Adobe 8".
Are other PDF readers vulnerable? Is one vulnerable if there is no PDF
reader?
===========Duh_OZ said:I have Adobe 8 on a W2K machine. It is vulnerable, at least on that
machine. Will try it on some XP boxes next.
Duh_OZ said:=========== Oops, cleared my cache, temp files, yaday, yada, yada and
now get "not allowed" while trying the links with the javascript
alerts appended on.
Here's a condensed test link: http://tinyurl.com/y4anpl
Vulnerable will have an alert '123' pop up.
===========
Oops, cleared my cache, temp files, yaday, yada, yada and now get "not
allowed" while trying the links with the javascript alerts appended on.
Here's a condensed test link: http://tinyurl.com/y4anpl
Vulnerable will have an alert '123' pop up.
============Ike said:I tried the above link on an XP with version 6 Acrobat that has not
been updated for a couple of years. I did not get a pop up. Either the
test is unreliable or version 6 does not have the problem.
I did have a problem running foxit with Adobe 7 installed. I'm a bitBeauregard said:No problem with that page for me, using Win2K, Firefox and FoxItReader.